skills/femto/skills/new-tag/Gen Agent Trust Hub

new-tag

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands for Git operations and build processes.\n
  • Evidence: SKILL.md defines a workflow using git status, git tag, git commit, git push, and pnpm build.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by acting on data from repository files.\n
  • Ingestion points: Workflow in SKILL.md involves inspecting .github/workflows/, package manifests, and release scripts.\n
  • Boundary markers: The skill does not implement delimiters or safety instructions when processing file content.\n
  • Capability inventory: The skill can push to remote repositories and execute build scripts via pnpm.\n
  • Sanitization: No sanitization or validation of the repository's configuration files is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 11:32 AM